Skip to content

chore(deps-dev): bump org.sonarsource.scanner.maven:sonar-maven-plugin from 5.2.0.4988 to 5.7.0.6970 - #1254

Merged
KochTobi merged 3 commits into
mainfrom
dependabot/maven/org.sonarsource.scanner.maven-sonar-maven-plugin-5.2.0.4988
Aug 12, 2026
Merged

chore(deps-dev): bump org.sonarsource.scanner.maven:sonar-maven-plugin from 5.2.0.4988 to 5.7.0.6970#1254
KochTobi merged 3 commits into
mainfrom
dependabot/maven/org.sonarsource.scanner.maven-sonar-maven-plugin-5.2.0.4988

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2025

Copy link
Copy Markdown
Contributor

Bumps org.sonarsource.scanner.maven:sonar-maven-plugin from 5.2.0.4988 to 5.7.0.6970.

Release notes

Sourced from org.sonarsource.scanner.maven:sonar-maven-plugin's releases.

5.7.0.6970

Release notes - Sonar Scanner for Maven - 5.7

Feature

SCANMAVEN-317 Support encryption of sonar.token, and other new secure properties SCANMAVEN-332 support modular-jar artifact type SCANMAVEN-341 Rework the support of encrypted properties

Maintenance

SCANMAVEN-370 Prepare next development iteration 5.7.0 SCANMAVEN-372 Configure Renovate for sonar-scanner-maven SCANMAVEN-373 SubmitReview: Use Vault token SCANMAVEN-374 Unpin internal GitHub actions SCANMAVEN-376 Use SonarSource/.../sonar-update-center-release@v1 instead of @​master SCANMAVEN-377 Update dependency org.assertj:assertj-core to v3.27.7 [SECURITY]

5.6.0.6792

Release notes - Sonar Scanner for Maven - 5.6

Maintenance

SCANMAVEN-318 Update Orchestrator and fix e2e matrix SCANMAVEN-324 Convert e2e tests to invoker SCANMAVEN-346 Fix CI failure SCANMAVEN-347 Automate detection of sonar:sonar shorthand failure SCANMAVEN-348 Bump org.assertj:assertj-core from 3.26.3 to 3.27.7 in /sonar-maven-plugin SCANMAVEN-349 Remove Maven 4 e2e tests from promotion requirements SCANMAVEN-356 Add automated release workflow SCANMAVEN-357 Licence packaging standard - Maven Scanner SCANMAVEN-358 Create SonarUpdateCenterRelease.yml SCANMAVEN-361 Add issue-categories in automated release SCANMAVEN-363 Fix e2e tests with Maven 4 SCANMAVEN-364 Do not run nightly builds on weekends SCANMAVEN-365 Set up orchestrator cache SCANMAVEN-366 Update sonar-scanner-java-library to 4.1.0.1619 SCANMAVEN-367 Update sonar-scanner-java-library to 4.1.1.1633 SCANMAVEN-369 Update parent pom to 87.0.0.3057

Feature

SCANMAVEN-281 Irrelevant encrypted properties are not filtered out in multi-module project with "sonar" in the name

5.5.0.6356

Release notes - Sonar Scanner for Maven - 5.5

Task

SCANMAVEN-339 Update parent pom to 86.0.0.3040 and scanner-java-library to 3.5.2.1586

5.4.0.6343

... (truncated)

Commits
  • 9e114d7 SCANMAVEN-332 Support modular-jar (#402)
  • 7424fe5 SCANMAVEN-317 - Support encryption of sonar.token, and other new secure prope...
  • b8ff39f SCANMAVEN-341 Fix regex for encrypted property filtering for mvn4 and add tes...
  • b4c0b4a SCANMAVEN-377 Update dependency org.assertj:assertj-core to v3.27.7 [SECURITY...
  • cd19506 SCANMAVEN-372 Configure Renovate (#393)
  • 944f552 SCANMAVEN-376 Use SonarSource/.../sonar-update-center-release@v1 instead of @...
  • 2832b8a SCANMAVEN-374 Unpin internal GitHub actions (#396)
  • 81caeeb SCANMAVEN-373 SubmitReview: Use Vault token (#395)
  • c62dd74 SCANMAVEN-370 Prepare next development iteration 5.7.0 (#392)
  • 8f1042a SCANMAVEN-369 Update parent pom to 87.0.0.3057 (#391)
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 1, 2025
@dependabot
dependabot Bot requested a review from a team September 1, 2025 20:00
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 1, 2025
@dependabot
dependabot Bot force-pushed the dependabot/maven/org.sonarsource.scanner.maven-sonar-maven-plugin-5.2.0.4988 branch from dd53925 to 6b6c000 Compare September 9, 2025 12:52
@dependabot
dependabot Bot force-pushed the dependabot/maven/org.sonarsource.scanner.maven-sonar-maven-plugin-5.2.0.4988 branch 3 times, most recently from 18afec7 to e7bc2dc Compare September 19, 2025 13:50
@KochTobi

Copy link
Copy Markdown
Contributor

@dependabot recreate

Bumps [org.sonarsource.scanner.maven:sonar-maven-plugin](https://github.com/SonarSource/sonar-scanner-maven) from 5.2.0.4988 to 5.7.0.6970.
- [Release notes](https://github.com/SonarSource/sonar-scanner-maven/releases)
- [Commits](SonarSource/sonar-scanner-maven@5.2.0.4988...5.7.0.6970)

---
updated-dependencies:
- dependency-name: org.sonarsource.scanner.maven:sonar-maven-plugin
  dependency-version: 5.2.0.4988
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump org.sonarsource.scanner.maven:sonar-maven-plugin from 5.0.0.4389 to 5.2.0.4988 chore(deps-dev): bump org.sonarsource.scanner.maven:sonar-maven-plugin from 5.2.0.4988 to 5.7.0.6970 Aug 12, 2026
@dependabot
dependabot Bot force-pushed the dependabot/maven/org.sonarsource.scanner.maven-sonar-maven-plugin-5.2.0.4988 branch from e7bc2dc to 22d39ab Compare August 12, 2026 11:18
@dependabot
dependabot Bot requested a review from a team as a code owner August 12, 2026 11:18
It seems that fastcsv introduced code signing on July 4 (osiegmar/FastCSV@6e07dc1). Checks out.
@KochTobi

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@sonarqubecloud

Copy link
Copy Markdown

@KochTobi
KochTobi merged commit 16d794d into main Aug 12, 2026
7 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/org.sonarsource.scanner.maven-sonar-maven-plugin-5.2.0.4988 branch August 12, 2026 12:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant